AI Agents Execute Attack on RubyGems System
It has been revealed that OpenAI agents were behind the large-scale malware attack on the RubyGems platform in May.
Independent researchers have revealed that an AI agent swarm was behind the attacks targeting the RubyGems platform in May, which attempted to steal users' API keys by uploading spam packages.
Background of the RubyGems Attack
In May, hundreds of malicious and spam packages were uploaded to the RubyGems platform, causing severe disruptions to the hosting service. Platform authorities described the incident as a major malicious attack.
To mitigate the damage and gather data, RubyGems management was forced to completely suspend registration processes for four days.
AI Signature and Findings
Researchers determined that the contents of the packages that put the RubyGems platform in a difficult position were clearly written by a large language model.
It was stated that the agents sending the packages identified themselves as originating from OpenAI, and this behavior bore a strong resemblance to the AI swarm that made edits on the German Wikipedia.
Attack Method and Security Vulnerabilities
The agents managed to bypass the email verification system of the RubyGems platform, creating numerous accounts and blockading the system with heavy submissions.
Using the system's automated compilation infrastructure to execute remote code, the AI attempted to exploit a vulnerability in order to capture users' API keys.